When Do You Need a Privileged Access Workstation?

By now we’ve established what a Privileged Access Workstation (PAW) is and why administrative endpoints form part of the privileged trust boundary.

The next question is perhaps the most important one.

Do you actually need one?

The answer is neither a simple yes nor a simple no.

Like most security decisions, the answer depends on risk.

Not every administrator performs the same tasks.

Not every privileged identity carries the same level of organisational impact.

And not every organisation has the same regulatory requirements, operational constraints or budget.

The goal isn’t to deploy a PAW for every administrator.

The goal is to provide an appropriate level of assurance for the identities that present the greatest risk if compromised.

Not All Privileged Identities Are Equal

Microsoft Entra includes dozens of administrative roles.

While they all provide elevated permissions, they don’t all carry the same level of organisational impact.

A compromised Global Administrator has vastly different consequences compared to a compromised Helpdesk Administrator.

Likewise, a Security Administrator has different responsibilities to an Exchange Administrator, and an Exchange Administrator carries different risks to someone responsible only for password resets.

Treating every administrative identity the same often leads to one of two outcomes.

Either every administrator receives the highest level of protection, which can be expensive and operationally difficult to maintain.

Or everyone receives the lowest common denominator, leaving your highest assurance identities insufficiently protected.

Neither approach is ideal.

Security Is About Risk

One of the biggest misconceptions surrounding PAWs is that Microsoft requires every administrator to use one.

That simply isn’t the case.

Microsoft provides guidance and best practices, but the decision ultimately belongs to the organisation.

This should be treated as a security architecture decision.

Security teams should assess:

  • Business impact
  • Threat exposure
  • Regulatory requirements
  • Operational practicality
  • Cost
  • Existing security controls

From there, the organisation decides which risks it wishes to mitigate and which risks it is prepared to accept.

That decision should be conscious, documented and reviewed regularly.

High Assurance Identities

Some identities naturally justify a higher level of assurance.

These often include roles such as:

  • Global Administrator
  • Privileged Role Administrator
  • Security Administrator

These identities have the ability to change authentication methods, assign administrative roles, modify Conditional Access policies, alter security controls and, ultimately, influence almost every aspect of a Microsoft Entra tenant.

For many organisations, these identities represent the strongest candidates for dedicated Privileged Access Workstations.

Administrative Roles That May Benefit

The next tier often includes operational administrators responsible for core Microsoft 365 services.

Examples include:

  • Exchange Administrator
  • SharePoint Administrator
  • Teams Administrator
  • Intune Administrator
  • Conditional Access Administrator

While these roles may not require the same level of assurance as Global Administrators, they still manage business-critical services and frequently perform privileged operations.

Many organisations choose dedicated Windows 365 Cloud PCs or Azure Virtual Desktop administrative environments for these identities.

Lower-Risk Administrative Roles

Not every administrative identity requires a dedicated administrative workstation.

Roles with more limited responsibilities may be adequately protected using a well-managed corporate device that has been appropriately hardened.

This might include:

  • User Administrator
  • Helpdesk Administrator
  • Password Administrator

The important point is that the decision should be based on the level of trust required, rather than simply whether an account holds an administrative role.

Introducing Trust Levels

This is where a Trust Level model becomes useful.

Rather than asking whether someone is an administrator, ask a different question.

How much trust does this identity require?

One possible approach is to group identities into different assurance levels.

Trust LevelTypical RolesExample Administrative Environment
TL1Global Administrator, Privileged Role Administrator, Security AdministratorDedicated Physical PAW or Dedicated Windows 365 Cloud PC
TL2Exchange, SharePoint, Teams, Intune, Conditional Access AdministratorsWindows 365 or Shared Azure Virtual Desktop
TL3User Administrator, Helpdesk AdministratorHardened Managed Device
TL4Standard UsersStandard Corporate Device

This isn’t a Microsoft standard.

It’s simply one example of how organisations can align workstation assurance with organisational risk.

The exact model should always reflect your own environment, business requirements and risk appetite.

It’s Not Just About Cost

Whenever PAWs are discussed, cost inevitably enters the conversation.

Dedicated hardware.

Windows 365 licences.

Azure Virtual Desktop.

Management overhead.

Support.

Training.

These are all valid considerations.

However, cost shouldn’t be viewed in isolation.

The question isn’t simply:

“How much does a PAW cost?”

The better question is:

“What would the compromise of this identity cost the organisation?”

When viewed through that lens, the conversation often changes.

Risk Acceptance

No organisation can eliminate every risk.

Every security programme involves balancing protection, usability and cost.

The important thing is that these decisions are made deliberately.

Choosing not to deploy a PAW for a particular administrative role is entirely reasonable if the organisation understands the associated risks and consciously accepts them.

The same is true in reverse.

If an identity presents a level of risk that exceeds the organisation’s tolerance, additional controls such as a dedicated Privileged Access Workstation may be justified.

Key Takeaways

A Privileged Access Workstation should never be viewed as an all-or-nothing security control.

Some identities require the highest possible level of assurance.

Others may be adequately protected through alternative administrative environments and strong endpoint security.

The objective isn’t to give every administrator a PAW.

The objective is to ensure the level of protection reflects the level of trust placed in the identity.

What’s Next?

If a Privileged Access Workstation is justified, what should it actually look like?

Should it always be a dedicated physical device?

Or have modern cloud services changed that conversation?

In the next article we’ll explore why dedicated physical Privileged Access Workstations continue to represent the highest level of assurance and where they still have an important role to play.